7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

IVRE

Open source

IVRE is a Python network reconnaissance framework that collects and analyzes scan and passive data, for building self-hosted alternatives to Shodan or Censys.

Open-source alternative to

ivre.rocks
IVRE homepage screenshot
GitHub stars
4.2k
Last commit
yesterday
Repository age
12 years
Version
v0.9.21
Licence
GPL-3.0
Self-hosted
Yes

About IVRE

IVRE, a French acronym also read as Dynamic Recon of UNKnown networks, is a network reconnaissance framework with tools for both passive and active recon. It lets security teams build their own, fully controlled alternatives to services like Shodan, ZoomEye, Censys and GreyNoise.

It ingests data from passive sources such as Zeek, Argus, Nfdump, p0f and airodump-ng, and from active tools including Nmap, Masscan, ZGrab2, ZDNS, Nuclei, httpx, dnsx, tlsx and Dismap. Uses listed by the project include running a passive DNS service, assembling a tailor-made external attack surface management tool, and collecting and analyzing network intelligence from your own sensors. Topics reference Nmap result analysis and OSINT.

IVRE is written in Python and licensed under GPL-3.0, and runs on your own infrastructure. It suits security researchers and defenders who work on networks they are authorized to scan. As with any scanning tool, use it only where you have permission.

Key features

  • Passive recon from Zeek and p0f data
  • Active scanning with Nmap and Masscan
  • Integration with Nuclei and httpx
  • Passive DNS service capability
  • External attack surface management
  • Searchable network intelligence database

Good fit for

  • →Building a private Shodan-like search
  • →Attack surface monitoring
  • →Analyzing Nmap scan results at scale
Built with
Python
Tags
network-recon
security
nmap
osint
easm
zeek
python
passive-dns

IVRE: questions and answers

What is IVRE used for?
IVRE is a Python network reconnaissance framework that collects and analyzes scan and passive data, for building self-hosted alternatives to Shodan or Censys. It is a good fit for building a private Shodan-like search, attack surface monitoring and analyzing Nmap scan results at scale.
Is IVRE open source?
Yes. IVRE is open source under the GPL-3.0 licence. Its source code is on GitHub at ivre/ivre and is written mainly in Python.
Is IVRE free?
Yes. IVRE is open source, so the software itself is free to use.
Can I self-host IVRE?
Yes. IVRE can be self-hosted on your own server or infrastructure; there is no official hosted version.
What is IVRE an alternative to?
IVRE is an open-source alternative to Shodan and Censys.
Is IVRE actively maintained?
Yes. The most recent commit to IVRE was on 1 October 2026, and the latest release is v0.9.21, published on 25 September 2024. The project has 4.2k stars on GitHub.

Open-source alternatives to IVRE

See all

SaaS alternatives to IVRE

See all